# Webhook connector generated invalid """ json elements

**URL:** <https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950>\
**Category:** Kibana\
**Created:** [January 28, 2024, 11:09pm UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950 "2024-01-28T23:09:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![garethhumphriesgkc](https://avatars.discourse-cdn.com/v4/letter/g/eb8c5e/32.png) [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Post date:** [January 28, 2024, 11:09pm UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950/1 "2024-01-28T23:09:02Z")

</div>

Hi,

I'm using the webhook connector to send some JSON data to a webhook destination whenever a rule triggers.

One of the JSON fields I'm sending is multiline, but anytime I try to embed `\n`s in the JSON, kibana converts it to a multi-line `"""` enclosed field.  
i.e., instead of:

```auto
 "field": "Multi-line value\ngoes\nhere"

```

I get:

```auto
 "field: """Multi-line value
goes
here"""

```

Obviously this isn't valid JSON, so the remote system is rejecting it. I haven't been able to find a way to stop Kibana from performing this conversion - I can double escape the newlines as `\\n`, but I still get the `"""` encoded strings, just with escaped newlines: `"field": """Multi-line value\ngoes\nhere"""`

It appears to happen if there's any `\` escaped char in the field, so you can't have any special chars in your strings if you want the resultant JSON to comply to the standard. I haven't found any documentation or discussion around this conversion or how to suppress it. Any ideas???

---

<div class="post-metadata">

**Author:** ![garethhumphriesgkc](https://avatars.discourse-cdn.com/v4/letter/g/eb8c5e/32.png) [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Post date:** [February 2, 2024, 2:18am UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950/2 "2024-02-02T02:18:41Z")

</div>

> <https://github.com/elastic/kibana/issues/175842>
>
> \*\*Kibana version:\*\*
> 8.11.1
> 
> \*\*Elasticsearch version:\*\*
> 8.11.1
> 
> \*\*Server OS… version:\*\*
> Cloud
> 
> \*\*Describe the bug:\*\*
> When using the webhook connector, if you include any string in the body that contains an escaped char, this field will get converted to \`"""\` encoded strings before saving. These strings, while convenient, are not part of the JSON standard and many endpoints don't recognise them. They appear to be sent to the endpoint in the encoded form without any ability to change.
> 
> e.g., if you want a field value of:
> \`\`\`
> "field": "Multi-line value\\ngoes\\nhere"
> \`\`\`
> You wilI actually get:
> \`\`\`
> "field": """Multi-line value
> goes
> here"""
> \`\`\`
> 
> 
> Double-escaped chars will still get a non-compliant string:
> \`"field": "Multi-line value\\\\ngoes\\\\nhere"\` becomes \`"field": """Multi-line value\\ngoes\\nhere"""\`
> 
> Even a simple \`" \\" "\` gets converted to \`""" " """\`
> 
> There doesn't appear to be a way via the GUI to disable or workaround this conversion.
> 
> Refer to https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950 
> 
> \*\*Steps to reproduce:\*\*
> 1. Create a webhook connector
> 2. Add a body, include a string field with an escaped char
> 3. Click save.
> 4. Re-open the body, observe the new format of string field
> 
> \*\*Expected behaviour:\*\*
> Kibana should save the JSON exactly as entered.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2024, 2:18am UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950/3 "2024-03-01T02:18:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
